As of September 27, 2026, Citrix is affected by vulnerabilities in the following products:
NetScaler ADC and NetScaler Gateway 14.1 Prior to 14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1 Prior to 13.1-64.23
NetScaler ADC FIPS Prior to 14.1-73.37 FIPS
Prior to 14.1-73.37 FIPS
NetScaler ADC FIPS and NDcPP Prior to 13.1-37.279
On September 27, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88771 and CVE-2026-88772 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778
Citrix Security Advisories
CISA KEV: CVE-2026-88771
CISA KEV: CVE-2026-88772
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
